What Is Typosquatting?

Typosquatting is the registration of a domain name that’s a slight misspelling or visual variant of a real brand’s domain, such as swapping a letter for a similar-looking number, so that customers who mistype the real address land on the fake one instead.
Why it matters
A typosquatted domain is rarely harmless. It’s most often used to run a phishing page that mimics the real site’s login or checkout flow, harvesting customer credentials or payment details under the brand’s name. Because the domain looks close enough to the real one at a glance, customers frequently don’t realise they’ve landed on a fake site until after they’ve entered sensitive information.
How it works
Typosquatters register domains using common typing mistakes, such as a doubled letter, a swapped adjacent key, or a numeral substituted for a similar-looking letter (a “1” for an “l”, a “0” for an “o”). The domain is then built to visually mirror the real site, sometimes closely enough to pass a quick glance, and often paired with an SSL certificate to avoid triggering a browser security warning.
In practice
A typosquatted domain for a well-known retailer might swap one letter in the brand name and clone the real site’s homepage and login page exactly. A customer who mistypes the URL, or clicks a link in a phishing email built around the same domain, sees a page that looks identical to the real one and enters their login details as normal, handing them straight to the attacker. Continuous domain monitoring is what catches this kind of registration before it’s actively harvesting data, rather than after the first customer reports it.
How Truviss helps
Truviss’s Domain Scanner runs 24/7 surveillance for newly registered lookalike and typosquatted domains targeting a brand, matching them against the brand’s real assets so genuine partner or reseller sites aren’t flagged by mistake, and files automated takedown requests with the registrar once a domain is verified as an infringement. This sits alongside the platform’s broader online brand protection coverage across marketplaces, social media and app stores.
Frequently asked questions
Look for domains that are one character different from the real one (a swapped, doubled, or missing letter, or a numeral substituted for a letter), especially if they use the same or a similar top-level domain. Automated domain monitoring catches these registrations as they happen, rather than relying on manual searching.
Registering a domain to deliberately impersonate another brand, particularly for phishing, generally breaches trademark law and most registrars’ acceptable use policies, which is why a documented takedown request to the registrar is usually effective.
Once a domain is verified as an infringement, a takedown request is filed directly with the registrar or host. Response times vary by registrar, but having a documented, evidence-backed request ready to file the moment a domain is detected is what keeps the exposure window short.